<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	xmlns:georss="http://www.georss.org/georss"
	xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
	
	>
<channel>
	<title>
	Comments on: More on Security Announcements	</title>
	<atom:link href="/articles/more-on-security-announcements/feed/" rel="self" type="application/rss+xml" />
	<link>/articles/more-on-security-announcements/</link>
	<description>Software Engineer and Consultant</description>
	<lastBuildDate>Sat, 29 Oct 2016 01:51:02 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>
		By: Basic Thinking Blog &#187; Wordpress: Ganz schlechtes Releasemanagement		</title>
		<link>/articles/more-on-security-announcements/comment-page-1/#comment-77</link>

		<dc:creator><![CDATA[Basic Thinking Blog &#187; Wordpress: Ganz schlechtes Releasemanagement]]></dc:creator>
		<pubDate>Sun, 21 Aug 2005 16:00:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.blackdown.de/2005/08/15/more-on-security-announcements/#comment-77</guid>

					<description><![CDATA[[...] Juergen looks at it as mine: I expect to get information about security issues from a central, easy-findable place from any project or product that has public exposure and more than a handful of users. (Yes, I expect that from open source projects too. Look around the net to see how good others handle it.) Expecting your users to gather information about a problem from forums, blogs, foreign sites, or the source code is simply unprofessional. [...]]]></description>
			<content:encoded><![CDATA[<p>[&#8230;] Juergen looks at it as mine: I expect to get information about security issues from a central, easy-findable place from any project or product that has public exposure and more than a handful of users. (Yes, I expect that from open source projects too. Look around the net to see how good others handle it.) Expecting your users to gather information about a problem from forums, blogs, foreign sites, or the source code is simply unprofessional. [&#8230;]</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jon Dowland		</title>
		<link>/articles/more-on-security-announcements/comment-page-1/#comment-75</link>

		<dc:creator><![CDATA[Jon Dowland]]></dc:creator>
		<pubDate>Wed, 17 Aug 2005 16:26:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.blackdown.de/2005/08/15/more-on-security-announcements/#comment-75</guid>

					<description><![CDATA[Agreed, utterly. A good start would be to use the announce list, so you didn&#039;t have to rely on randomly stumbling across the page to learn you&#039;re vulnerable to 10s of security holes.

But once that hurdle is passed, I hope that one-day we&#039;ll get point releases with *just* the security problem solved. That&#039;d make distributing WP with things like Debian GNU/Linux feasible.]]></description>
			<content:encoded><![CDATA[<p>Agreed, utterly. A good start would be to use the announce list, so you didn&#8217;t have to rely on randomly stumbling across the page to learn you&#8217;re vulnerable to 10s of security holes.</p>
<p>But once that hurdle is passed, I hope that one-day we&#8217;ll get point releases with *just* the security problem solved. That&#8217;d make distributing WP with things like Debian GNU/Linux feasible.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
